Skip to main content
Fig. 3 | IPSJ Transactions on Computer Vision and Applications

Fig. 3

From: Attacking convolutional neural network using differential evolution

Fig. 3

Geometrical illustration of few-pixel attack. An illustration of conducting two-pixel perturbation attack in a 3D input space coordinate (i.e., the image has three pixels). The original natural image is a data point represented by S1. Due to the limitation on the number of dimensions that can be probed, in each iteration, the search is only allowed on a 2D plane (shown by green, blue, and orange planes in the figure) around the current solution. As shown, after three iterations which the direction of probe is shown by yellow arrows, it finds the optimal point. By iterating the evolution of DE, the 2D probe can actually move in towards arbitrary directions in 3D space to find the optima

Back to article page